Security & Compliance

Enterprise-Grade Security

Your manuscripts are valuable. We protect them with bank-level encryption and industry-leading security practices.

Security by Design

Every layer of our infrastructure is designed with security as a top priority.

TLS 1.2+
Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2+ with modern cipher suites.

AES-256
Encryption at Rest

Files and database records are encrypted using AES-256 encryption, protecting your data even if physical storage is compromised.

Enterprise Cloud
Secure Infrastructure

Hosted on enterprise-grade cloud infrastructure with redundancy, automatic failover, and 99.9% uptime SLA.

RBAC
Access Controls

Role-based access controls (RBAC) ensure only authorized personnel can access sensitive systems and data.

Infrastructure & Data Protection

Hosting

Cloud Provider: Tier-1 enterprise cloud infrastructure

Database: Distributed database with automatic failover and redundancy

Storage: Encrypted object storage with versioning and backup

Encryption

In Transit: TLS 1.2+ with perfect forward secrecy

At Rest: AES-256 for all files and database records

Secrets: Hardware security module (HSM) backed encryption

Monitoring

Audit Logs: Immutable logs of all admin actions

Access Control: Role-based permissions with least privilege

Intrusion Detection: 24/7 automated threat monitoring

Compliance & Certifications

We meet the highest standards for data protection and privacy.

GDPR Compliant

Full compliance with EU General Data Protection Regulation for customer privacy.

SOC 2 Type II

Independent audit of our security, availability, and confidentiality controls.

ISO 27001

Information security management system certified to international standards.

Data Retention & Deletion

Job Artifacts

Translation files and job data are retained for 30 days by default. Enterprise customers can configure custom retention periods.

Billing Records

Billing and audit records are retained for a minimum of 7 years for tax and compliance purposes.

Account Deletion

Deleted accounts purge personal data within 30 days. Audit logs are pseudonymized but retained for security purposes.

GDPR Rights

You can request data export or deletion at any time. See our Privacy Policy for details.

Third-Party Security

We carefully vet all third-party providers to ensure they meet our security standards:

Payment Processing

PCI DSS Level 1 certified payment processor

Cloud Infrastructure

SOC 1/2/3, ISO 27001 certified providers

AI Translation

Enterprise agreements with data processing addendums

Data Storage

Encrypted backups with point-in-time recovery

Report a Security Issue

If you discover a security vulnerability, please report it to our security team immediately. We take all reports seriously and will respond within 24 hours.

We appreciate responsible disclosure and will acknowledge contributors who help us improve our security posture.